Australian medical clinic delayed notifying patients of data breach for months
Translated from English, summarized and contextualized by DistantNews.
At a glance
- GO2 Health, a medical clinic in Brisbane, Australia, experienced a data breach in April due to a phishing attack.
- Patients were notified nearly three months later, on July 16, after the clinic investigated the extent of the breach.
- The breach potentially exposed patients' Department of Veteran's Affairs ID numbers and other information provided via email, though primary patient records were not accessed.
GO2 Health, a medical clinic in Everton Park, Brisbane, has disclosed a data breach that occurred in April following a phishing attack on its primary email mailbox. The clinic waited almost three months, until July 16, to notify affected patients about the incident.
Unfortunately, our investigation did ultimately identify that some data within the mailbox may have been accessed, including some patients' Department of Veteran's Affairs ID Numbers and other information that our patients may have provided the inbox.
A spokesperson for GO2 Health, which provides general practice and veteran care services, stated that cybersecurity experts were engaged to contain the breach and that staff using the affected mailbox were altered on April 24. The investigation confirmed that some data within the mailbox may have been accessed. This included patients' Department of Veteran's Affairs ID numbers and other personal information submitted via email. Crucially, the clinic emphasized that its primary patient information system was not compromised.
Importantly, there was no access to the system where we primarily store patient information, and the mailbox uses an auto-archive, so the data accessed only pertains to emails sent during the previous 12 months leading up to the incident.
The accessed data was limited to emails sent within the 12 months preceding the incident, due to the mailbox's auto-archive function. GO2 Health alerted the Office of the Australian Information Commissioner (OAIC) on May 18, as required by regulations for breaches likely to cause serious harm. The clinic explained the delay in patient notification was to avoid causing undue concern and to ensure accurate information was communicated after a thorough investigation.
We wanted to avoid causing undue concern and confusion by notifying the wrong people, or communicating inaccurate information.
However, one affected patient, Amanda, expressed frustration over the delay, stating that the three-month wait meant individuals missed a critical window to monitor their accounts and change passwords. As a veteran receiving treatment, she highlighted the sensitive nature of the information potentially exposed, expressing concern about its future misuse. Cybersecurity experts are calling for stricter regulations on medical data handling and earlier patient notification following breaches, given the highly sensitive information clinics manage.
I think they've wasted really precious time for people to check their accounts and change their passwords.
Originally published by ABC Australia in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.